CVE-2019-20454
14.02.2020, 14:15
An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in do_extuni_no_utf in pcre2_jit_compile.c.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pcre | pcre2 | 10.31 ≤ 𝑥 < 10.34 |
| splunk | universal_forwarder | 8.2.0 ≤ 𝑥 < 8.2.12 |
| splunk | universal_forwarder | 9.0.0 ≤ 𝑥 < 9.0.6 |
| splunk | universal_forwarder | 9.1.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libpcre2-16-0 |
| ||||||||||||||||
| libpcre2-32-0 |
| ||||||||||||||||
| libpcre2-8-0 |
| ||||||||||||||||
| libpcre2-posix2 |
| ||||||||||||||||
| pcre2-devel |
|
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
References